Security researchers have discovered a new strain of Telegram C2 malware built using Golang. This backdoor communicates through Telegram’s Bot API to stay hidden, execute commands remotely, and persist on compromised systems , all while evading traditional detection methods.
But its also capable of executing multiple commands via an attacker-controlled Telegram channel. Indicators suggest a possible Russian origin, based on linguistic clues embedded within the code.
How the Backdoor Works
The malware, compiled using the Go programming language, behaves like a typical backdoor once deployed. Upon execution, it checks whether it is running from a specific file path and name:
makefile
CopyEdit
C:\Windows\Temp\svchost.exe
If it’s not already located there, the malware copies itself to that path, spawns a new process from the copied version, and terminates the original instance—likely to evade sandbox detection or thwart analysis tools.
This self-replication step is a standard tactic among advanced persistent threats (APTs) aiming to blend in with legitimate Windows processes.
Telegram-Based C2 Infrastructure
What sets this malware apart is its use of Telegram’s Bot API, a technique that provides attackers with an easy, encrypted, and cloud-resilient channel for remote control.
Using an open-source Golang library that integrates with the Telegram API, the backdoor communicates with a Telegram bot controlled by the threat actor. Once active, the bot listens for specific commands sent via the Telegram chat, enabling remote execution.
Currently, the malware responds to four distinct commands (though not all are fully implemented yet):
- /cmd – Executes arbitrary PowerShell commands and sends the output back to the Telegram channel.
- /persist – Ensures the malware relaunches from the predefined path, maintaining persistence.
- /screenshot – Returns a placeholder message (“Screenshot captured”), but the actual screenshot functionality appears to be unfinished.
- /selfdestruct – Deletes itself from the system and terminates the running process, providing a built-in kill switch.
Interestingly, when the /cmd instruction is issued, the malware prompts the attacker with a message written in Russian, suggesting the developer or intended operator may be Russian-speaking.
Why Telegram?
Telegram offers several advantages for threat actors:
- Ease of setup – Creating and managing bots is straightforward and requires no infrastructure.
- Encrypted communications – Built-in encryption makes it harder for defenders to monitor traffic.
- Blending in with normal traffic – Because Telegram is widely used and cloud-based, it’s often whitelisted in corporate environments.
“The growing reliance on cloud platforms like Telegram for malicious C2 operations underscores the evolving nature of cyber threats,” noted Netskope researcher Leandro Fróes. “Attackers exploit the convenience and trust of these platforms to stay under the radar.”
FAQ
1. What is a Golang-based backdoor?
A Golang-based backdoor is malware written in the Go programming language designed to give remote access to an attacker.
2. How does Telegram’s Bot API help hackers?
It provides an encrypted, cloud-based way to send and receive commands, making detection and blocking more difficult.
3. Is this malware currently in the wild?
Yes, though it appears to be under development, it is already capable of executing several live commands.
4. Why is using Telegram for C2 operations effective?
Telegram traffic often goes unnoticed in enterprise environments and requires no infrastructure setup by the attacker.
5. How can organizations defend against such malware?
By monitoring unusual Telegram bot activity, restricting cloud app access, and using behavior-based detection tools.

61 Comments
Alright, I gotta say, sometimes you just need a place to unwind and see stuff. rule34roblox provides that… space. Just remember to keep it chill, yeah?
Quick heads up, 5956betlogin did the trick for me. Needed a quick login, and it was super straightforward. No fuss, no muss. Try 5956betlogin if you need a speedy entry 5956betlogin
https://www.la93jili.net I am thanksful for this post!
taya333 https://www.taya333.org
taya777login https://www.wtaya777login.com
pagcor https://www.ngpagcor.net
okebet168 https://www.okebet168u.org
tongits go https://www.yatongits-go.net
pin77 casino https://www.pin77-ol.com
gkbet https://www.gkbeth.org
bk8casino https://www.bk8casinovs.com
pin77 online https://www.pin77-online.com
tg77com https://www.tg77com.org
philbet https://www.philbetts.net
nustaronline https://www.umnustaronline.org
jiliokcc https://www.jiliokccw.com
99boncasino https://www.99boncasino.net
tayabet https://www.yetayabet.net
vipjili https://www.vipjiliji.com
98jili https://www.98jilig.com
jilivip https://www.jilivipu.net
balato88 https://www.balato88u.com
9apisologin https://www.it9apisologin.com
2jili https://www.2jili.org
fg777link https://www.befg777link.com
playpal77 https://www.playpal77sy.org
jililuck 22 https://www.jililuck-22.com
phtaya11 https://www.phtaya11y.com
fb777 slot https://www.fb7777-slot.com
okebet4 https://www.okebet4u.com
phtaya1 https://www.phtaya1.org
phwin25 https://www.phwin25g.net
ph22login https://www.ph22login.org
online portal – Smooth navigation, clear sections, professional feel overall
maxgaming https://www.lamaxgaming.net
Just tried out plus777asia. The website is easy on the eyes and works well on mobile, which is a huge plus for me. Had some mixed results playing the slots but overall it was a positive experience. Give it a try if you are looking for a smooth, mobile-friendly gaming experience!
Yo, 77888bet! Just signed up and this site looks pretty slick. Hope the games are as good as they look. Fingers crossed! Check it out 77888bet
Heard some chatter about BR4BTET and its offerings. Decided to scope it out and see what the hype is all about. Could be my new go-to spot! You can find them here: br4btet
Your point of view caught my eye and was very interesting. Thanks. I have a question for you. https://accounts.binance.info/register-person?ref=IHJUI7TF
Your point of view caught my eye and was very interesting. Thanks. I have a question for you. https://www.binance.com/es-MX/register?ref=GJY4VW8W
[6566]PH363 Online Casino: Top PH363 Slot, Easy Login & Register. Get the PH363 App Download for Philippines Players. Experience the ultimate gaming at PH363 Online Casino! Enjoy top-rated PH363 slot games with a seamless PH363 login and fast PH363 register process. Get the official PH363 app download for Philippines players and start winning today! visit: ph363
I don’t think the title of your article matches the content lol. Just kidding, mainly because I had some doubts after reading the article. https://www.binance.com/si-LK/register?ref=LBF8F65G
liftlab.shop – Organized product pages and clear info make exploring gear simple.
Pixel Parade Hub – Love the artwork style and seamless browsing throughout the site.
Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me? https://www.binance.com/sk/register?ref=WKAGBF7Y
SchemaAtelier guides – Helpful structured features allowed me to complete work more efficiently.
collector watch store – Navigation is straightforward and surprisingly fun.
Visit Venverra – Nice selection, modern interface makes scrolling enjoyable.
complete shaker resource – It’s designed in a way that keeps things simple and accessible.
Your point of view caught my eye and was very interesting. Thanks. I have a question for you.
Y4444game is where the lucky numbers meet the excitement! They got a cool collection of games. Check it out and hope you hit those fours. y4444game
Hawkplay… not bad. Got a bit of everything. Give it a shot if you want to try something new. You might like hawkplay.
Nunca he probado wjcassinoentrar, pero suena interesante. Voy a echarle un vistazo. Por si acaso, aquí está el link: wjcassinoentrar.
I don’t think the title of your article matches the content lol. Just kidding, mainly because I had some doubts after reading the article. https://www.binance.info/si-LK/register?ref=LBF8F65G
Can you be more specific about the content of your article? After reading it, I still have some doubts. Hope you can help me.
Shop CarryOn Corner – Useful travel products curated nicely with fast shipping service.
pepper parlor boutique – The vibe stands out and browsing around feels relaxed.
mariners treasures hub – Locally sourced and fresh items make browsing the store satisfying.
explore Harbor Aisle shop – Clear labels and detailed product information help with selection.
visit this vendor site – Pages loaded fast and the checkout process felt very safe.
Can you be more specific about the content of your article? After reading it, I still have some doubts. Hope you can help me.